Description
ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.
Remediation
References
Related Vulnerabilities
Oracle JRE Observable Discrepancy Vulnerability (CVE-2024-21208)
WordPress Plugin Advanced XML Reader XML External Entity Information Disclosure (0.3.4)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-0929)
WordPress Plugin Woocommerce Product Designer Arbitrary File Upload (3.0.3)